Malware

Cerbu.146505 removal tips

Malware Removal

The Cerbu.146505 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.146505 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Cerbu.146505?


File Info:

name: B0328FC5A3DF46D2E358.mlw
path: /opt/CAPEv2/storage/binaries/77ee4cd52349829672aac989ec9162cd71306c1001bac623441ebc0fca53add0
crc32: EC0C0B32
md5: b0328fc5a3df46d2e35881875f5324ed
sha1: 92881b3c17d77a9049665f117f4acc2b4e4d5e6f
sha256: 77ee4cd52349829672aac989ec9162cd71306c1001bac623441ebc0fca53add0
sha512: 8fe543a4eb35d0368160c4be098c736dea5db326ba3addc2649441c41c1bb8eeea57247990b50e4e3334cd9ed537edea4343bd47ad18244d1a56229b7972ed13
ssdeep: 3072:ikeJ2oRCjMBphVSDevmx73Yz7Mv/M13Qz1OnKMvkeJ2oRCjMBpXJqY:ikeJ2onSDevmxzw7513s1F2keJ2oFq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16814E571B08BE016E86DB071C85AA6FF404EFDA8C553480B7E843F6EB6F6216735650A
sha3_384: 304ca7eef1eccb1b271b1dd206e6fcead68f04bb98c33e83143ff76c5ccb91755ed55555da674550f1f42a1cb743556e
ep_bytes: ff250020400000000000000000000000
timestamp: 2039-04-28 23:47:35

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: Fix Browser
FileVersion: 1.0.0.0
InternalName: MDP_Reward.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: MDP_Reward.exe
ProductName: FixBrowser
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Cerbu.146505 also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Cerbu.4!c
MicroWorld-eScanGen:Variant.Cerbu.146505
FireEyeGen:Variant.Cerbu.146505
ALYacGen:Variant.Cerbu.146505
CylanceUnsafe
AlibabaTrojan:MSIL/DropperX.bb5d17c0
BitDefenderThetaGen:NN.ZemsilF.34786.mm0@aGkp2Mh
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Agent.VMS
TrendMicro-HouseCallTROJ_GEN.R002H09G722
Paloaltogeneric.ml
BitDefenderGen:Variant.Cerbu.146505
AvastWin32:DropperX-gen [Drp]
Ad-AwareGen:Variant.Cerbu.146505
EmsisoftGen:Variant.Cerbu.146505 (B)
VIPREGen:Variant.Cerbu.146505
McAfee-GW-EditionArtemis
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Cerbu.146505
AviraTR/Agent.xbtor
MAXmalware (ai score=80)
ArcabitTrojan.Cerbu.D23C49
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.R503183
McAfeeArtemis!B0328FC5A3DF
APEXMalicious
RisingTrojan.Agent!8.B1E (CLOUD)
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.VMS!tr
AVGWin32:DropperX-gen [Drp]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Cerbu.146505?

Cerbu.146505 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment